Description
A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects unknown code. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Request Forgery
Action: Monitor
AI Analysis

Impact

A weakness has been identified in gedelumbung HospitalManagement up to commit c2d45543789a3887067d3915f69d44cfc2cf76a8 that allows attackers to perform cross‑site request forgery (CSRF). The flaw permits an attacker to trick a legitimate user into submitting unwanted requests to the application, potentially leading to unauthorized state changes. This attack exploits the absence of CSRF protections and, according to the CWE mapping, relates to CWE‑352 and possibly a missing authorization check (CWE‑862).

Affected Systems

The vulnerability affects the gedelumbung HospitalManagement application, represented by the vendor/product pair gedelumbung:HospitalManagement. Because the project uses a rolling‑release model, specific version numbers for affected or patched releases are not available, but all instances prior to commit c2d45543789a3887067d3915f69d44cfc2cf76a8 are potentially vulnerable.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, so it is not yet known to be actively exploited in the wild. Based on the description, it is inferred that the attack requires an attacker to entice an authenticated user to visit a malicious site or click a link, after which the victim’s session is used to perform state‑changing requests. The public availability of an exploit and the ability to launch the attack remotely suggest that an attacker with a legitimate session could gain unintended access. The risk is contingent on users interacting with untrusted sites while authenticated, and on the presence of state‑changing actions that lack proper CSRF defenses.

Generated by OpenCVE AI on September 19, 2026 at 18:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest release of HospitalManagement from the project's GitHub repository when it includes a CSRF fix, and regularly monitor the repository for updates.
  • Implement per‑request anti‑CSRF tokens for all state‑changing endpoints and validate them server‑side before processing the request.
  • Configure session cookies to have the SameSite attribute set to Strict, and verify the Referer and Origin headers for sensitive operations to mitigate CSRF.

Generated by OpenCVE AI on September 19, 2026 at 18:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects unknown code. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
Title gedelumbung HospitalManagement cross-site request forgery
First Time appeared Gedelumbung
Gedelumbung hospitalmanagement
Weaknesses CWE-352
CWE-862
CPEs cpe:2.3:a:gedelumbung:hospitalmanagement:*:*:*:*:*:*:*:*
Vendors & Products Gedelumbung
Gedelumbung hospitalmanagement
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Gedelumbung Hospitalmanagement
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-18T16:19:35.558Z

Reserved: 2026-09-18T08:50:43.661Z

Link: CVE-2026-93531

cve-icon Vulnrichment

Updated: 2026-09-18T16:19:27.439Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:14.773

Modified: 2026-09-18T19:14:56.310

Link: CVE-2026-93531

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:45:14Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-862

    Missing Authorization